Courses from 1000+ universities
AI got cheap enough that Duolingo’s most expensive plan may not survive it. I read the earnings call transcript and opened the app to see what is actually changing for learners.
600 Free Google Certifications
Artificial Intelligence
IT & Networking
Software Engineering
Supporting Victims of Domestic Violence
Know Thyself - The Value and Limits of Self-Knowledge: The Examined Life
Understanding Dementia
Organize and share your learning with Class Central Lists.
View our Lists Showcase
Explores exploitation techniques for cryptocurrency hacking across vulnerable Web3 infrastructure, nodes, transaction flows, private keys, and ERC20 smart contracts.
A vulnerability chain bypasses macOS security protections on Apple Silicon and Intel devices, demonstrated from one-click execution to complete takeover.
Explores EDR internals and demonstrates Windows API injection, function unhooking, and custom syscall techniques for evasion.
Explore reliable Linux kernel exploitation techniques for turning a limited use-after-free vulnerability into root privilege escalation on Ubuntu 22.04.
A walkthrough of discovering and exploiting a remote stack overflow in a Linux kernel network module, revealing the low-level exploit development process.
Examines newly discovered WPA3 and Management Frame Protection vulnerabilities, including client-disconnection and router-crash attacks, with proof-of-concepts in a Wi-Fi testing framework.
Explore how race conditions and TOCTOU flaws arise in web applications and how attackers test them through live demos and a distributed penetration-testing tool.
A cybersecurity research talk on using knowledge graphs for trust analysis to uncover identity-platform privilege escalation and impersonation weaknesses.
Explore Mixed Boolean-Arithmetic transformations for building obfuscation primitives, from opaque predicates to virtualization-based VM handlers.
A deep dive into Kyocera printer vulnerabilities, including pre-authentication remote code execution, arbitrary file reading, password leakage, and office-network compromise.
Examines how simulated execution can improve malicious-text detection against obfuscation while reducing false positives and addressing dynamic-analysis trade-offs.
An examination of 35 cryptocurrency scam types, from familiar pump-and-dump schemes to Web3-specific rug pulls and NFT airdrop scams.
Explores server-side template injection against hardened Flask/Jinja2 and Express/Vue environments using Python tooling and progressively difficult challenges.
Examines how hardcoded Twitter API credentials in mobile apps enable account takeover, bot activity, and sensitive actions, and how to prevent such leaks.
Learn how virtualized digital twins of PLCs and other OT devices can safely reproduce industrial networks for vulnerability research and penetration testing.
Get personalized course recommendations, track subjects and courses with reminders, and more.